alert syslog $EXTERNAL_NET any -> $HOME_NET any (msg:"[ARP] arpwatch - Changed network interface for IP address"; content: "changed ethernet address"; classtype: suspicious-traffic; program: arpwatch; parse_src_ip: 1; reference: url,wiki.quadrantsec.com/bin/view/Main/5000065; sid: 5000065; rev:4; )
-- Main.Sagan-Wiki-Add - 2015-10-21
New revisions of 5000065 will be below...